Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-37785— ext4: fix OOB read when checking dotdot dir

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_empty_dir函数在检查dotdot目录时可能导致越界读取。

CVSS 7.8 · High EPSS 0.30% · P21

Possible ATT&CK Techniques 1 AI

T1406.004

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux ac27a0ec112a089f1a5102bc8dffc79c8c815571< 14da7dbecb430e35b5889da8dae7bef33173b351 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< e47f472a664d70a3d104a6c2a035cdff55a719b4 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b7531a4f99c3887439d778afaf418d1a01a5f01b affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 89503e5eae64637d0fa2218912b54660effe7d93 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 52a5509ab19a5d3afe301165d9b5787bba34d842 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b47584c556444cf7acb66b26a62cbc348eb92b78 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< ac28c5684c1cdab650a7e5065b19e91577d37a4b affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 53bc45da8d8da92ec07877f5922b130562eb4b00 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-37785

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ext4: fix OOB read when checking dotdot dir
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed). ext4_empty_dir() assumes every ext4 directory contains at least '.' and '..' as directory entries in the first data block. It first loads the '.' dir entry, performs sanity checks by calling ext4_check_dir_entry() and then uses its rec_len member to compute the location of '..' dir entry (in ext4_next_entry). It assumes the '..' dir entry fits into the same data block. If the rec_len of '.' is precisely one block (4KB), it slips through the sanity checks (it is considered the last directory entry in the data block) and leaves "struct ext4_dir_entry_2 *de" point exactly past the memory slot allocated to the data block. The following call to ext4_check_dir_entry() on new value of de then dereferences this pointer which results in out-of-bounds mem access. Fix this by extending __ext4_check_dir_entry() to check for '.' dir entries that reach the end of data block. Make sure to ignore the phony dir entries for checksum (by checking name_len for non-zero). Note: This is reported by KASAN as use-after-free in case another structure was recently freed from the slot past the bound, but it is really an OOB read. This issue was found by syzkaller tool. Call Trace: [ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710 [ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375 [ 38.595158] [ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1 [ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 38.595304] Call Trace: [ 38.595308] <TASK> [ 38.595311] dump_stack_lvl+0xa7/0xd0 [ 38.595325] print_address_description.constprop.0+0x2c/0x3f0 [ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595349] print_report+0xaa/0x250 [ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595368] ? kasan_addr_to_slab+0x9/0x90 [ 38.595378] kasan_report+0xab/0xe0 [ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595400] __ext4_check_dir_entry+0x67e/0x710 [ 38.595410] ext4_empty_dir+0x465/0x990 [ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10 [ 38.595432] ext4_rmdir.part.0+0x29a/0xd10 [ 38.595441] ? __dquot_initialize+0x2a7/0xbf0 [ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10 [ 38.595464] ? __pfx___dquot_initialize+0x10/0x10 [ 38.595478] ? down_write+0xdb/0x140 [ 38.595487] ? __pfx_down_write+0x10/0x10 [ 38.595497] ext4_rmdir+0xee/0x140 [ 38.595506] vfs_rmdir+0x209/0x670 [ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190 [ 38.595529] do_rmdir+0x363/0x3c0 [ 38.595537] ? __pfx_do_rmdir+0x10/0x10 [ 38.595544] ? strncpy_from_user+0x1ff/0x2e0 [ 38.595561] __x64_sys_unlinkat+0xf0/0x130 [ 38.595570] do_syscall_64+0x5b/0x180 [ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_empty_dir函数在检查dotdot目录时可能导致越界读取。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ac27a0ec112a089f1a5102bc8dffc79c8c815571 ~ 14da7dbecb430e35b5889da8dae7bef33173b351 -
Linux Linux 2.6.19 -

II. Public POCs for CVE-2025-37785

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-37785

请登录查看更多情报信息。

Patches & Fixes for CVE-2025-37785 (1)

Other References for CVE-2025-37785 (8)

Same Patch Batch · Linux · 2025-04-18 · 23 CVEs total

CVE-2025-39930 8.4 HIGH ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()
CVE-2025-40364 7.8 HIGH io_uring: fix io_req_prep_async with provided buffers
CVE-2025-37838 7.8 HIGH HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Con
CVE-2025-37893 7.8 HIGH LoongArch: BPF: Fix off-by-one error in build_prologue()
CVE-2025-39688 7.5 HIGH nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()
CVE-2025-39735 7.1 HIGH jfs: fix slab-out-of-bounds read in ea_get()
CVE-2025-37860 sfc: fix NULL dereferences in ef100_process_design_param()
CVE-2025-37925 jfs: reject on-disk inodes of an unsupported type
CVE-2025-38049 x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors
CVE-2025-38104 drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversi
CVE-2025-38152 remoteproc: core: Clear table_sz when rproc_shutdown
CVE-2025-38240 drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr
CVE-2025-38479 dmaengine: fsl-edma: free irq correctly in remove path
CVE-2025-38575 ksmbd: use aead_request_free to match aead_request_alloc
CVE-2025-38637 net_sched: skbprio: Remove overly strict queue assertions
CVE-2025-39728 clk: samsung: Fix UBSAN panic in samsung_clk_init()
CVE-2025-39755 staging: gpib: Fix cb7210 pcmcia Oops
CVE-2025-39778 objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show()
CVE-2025-39989 x86/mce: use is_copy_from_user() to determine copy-from-user context
CVE-2025-40014 objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq()

Showing top 20 of 23 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37785

No comments yet


Leave a comment